TL;DR

September 2026 Patch Tuesday landed 974 CVEs — a new record, nearly double August’s. Two were already exploited in the wild and hit CISA KEV the same day (CVE-2026-81963 and CVE-2026-85880). But the real story is the cluster of ~20 unauthenticated, wormable RCEs across core Windows infrastructure: DNS (CVE-2026-69730), Netlogon (CVE-2026-72982), DHCP (CVE-2026-69845 / CVE-2026-72979), MSMQ (CVE-2026-69579), NFS (CVE-2026-69595 / CVE-2026-78445), and SSTP (CVE-2026-73009), all CVSS 9.8. Add Kerberos capture-replay (CVE-2026-69676, CVSS 8.8), and you have 12 unauthenticated network-reachable RCEs in the identity/infrastructure layer alone. Patch priority should follow network exposure, not CVSS — the 9.8 DNS flaw is more urgent on a domain controller than a 9.1 Office flaw on a workstation sitting behind a firewall.

The record count, but the count isn’t the threat

Microsoft released 974 CVEs on September 8, obliterating its previous single-Patch-Tuesday record of 570 set in July. 258 were RCEs. 113 were rated Critical. Two were actively exploited: CVE-2026-81963 (Windows Update Stack link-following EoP to SYSTEM) and CVE-2026-85880 (ALPC heap overflow, escaping AppContainer to SYSTEM). Both hit CISA KEV the same day they shipped.

The 974 number will be on every headline. The number that matters for your network is closer to 20: the unauthenticated, no-user-interaction RCEs that let a remote attacker with network access execute code and move on.

The wormable cluster

Trend Micro’s Zero Day Initiative identified ~20 wormable CVEs. CrowdStrike independently flagged 17+ across DNS, DHCP, MSMQ, NFS, and SSTP. Here’s the network map:

DNS — CVE-2026-69730 (CVSS 9.8)

ZDI called it “SigRed’s spiritual successor.” An unauthenticated attacker sends a crafted packet to DNS and gets arbitrary code execution. In AD environments, DNS co-locates on domain controllers, so a successful hit lands you on a DC — immediate NTDS.dit access, Kerberos keys, and the ability to forge any ticket in the domain. CVE-2026-69858 is a similar flaw.

Netlogon — CVE-2026-72982 (CVSS 9.8)

Unauthenticated crafted packet → code execution on the target system. Netlogon runs on every DC and listens across the network by design. This isn’t a service you hide behind a firewall. Successful exploitation means you’re inside the authentication layer that every other domain service trusts.

DHCP — CVE-2026-69845 / CVE-2026-72979 (CVSS 9.8 each)

Heap overflow and use-after-free, both unauthenticated. DHCP servers run with elevated privileges and configure every endpoint on the network. A compromised DHCP server is a pivot point security monitoring routinely overlooks.

MSMQ — CVE-2026-69579 (CVSS 9.8)

Use-after-free in the network-facing packet handling path. TCP 1801. Often left running as a leftover service in environments that haven’t audited their role inventory.

NFS ONCRPC — CVE-2026-69595 / CVE-2026-78445 (CVSS 9.8 each)

Unauthenticated crafted packet → arbitrary code execution on the NFS service. Port 2049. The exposure profile depends on where NFS has been deployed — storage servers, file shares, development environments.

SSTP VPN — CVE-2026-73009 (CVSS 9.8)

Unauthenticated crafted packet to the SSTP listener → RCE. SSTP is the Microsoft-native VPN protocol, supported out-of-the-box by Windows Server RRAS. If you run an SSTP VPN and it’s internet-facing, this is the one to patch today.

Kerberos — CVE-2026-69676 (CVSS 8.8)

Capture-replay attack on Kerberos authentication. An attacker who has low-privileged credentials intercepts a legitimate Kerberos exchange, replays a modified variant, and executes code. ZDI rates “Exploitation More Likely.” No user interaction beyond having the session active.

Hyper-V — CVE-2026-69603 (CVSS 8.8) / CVE-2026-80083 (CVSS 8.8)

Heap overflow via malformed hypercall payload and untrusted pointer dereference. Both let a guest app escape to the host. CVE-2026-72961 (CVSS 8.2) overflows vTPM state to escalate from host admin to VTL1.

The patch that wasn’t enough: ShieldCrash

Two hours after Patch Tuesday, MSNightmare (of the Nightmare-Eclipse persona) dropped a PoC zero-day called ShieldCrash targeting CVE-2026-69414 (ShieldBreak) in the Microsoft Malware Protection Engine. Microsoft’s patch was incomplete — one missed spot still allows arbitrary file reads as SYSTEM. The PoC was on GitHub by September 7, two days after the patches shipped. 274 stars in a week.

This is worth emphasizing: Microsoft patched the vulnerability, validated it, shipped the update, and the attacker found a second attack path within hours. Patching is not the same as closing the surface. CVE-2026-69414 sits at CVSS 7.8 (local, low privileges → SYSTEM) and affects the Malware Protection Engine on every supported Windows version. ShieldBreak was the first patch. ShieldCrash is the second attack against the same component.

Why CVSS should be your secondary sort key

Most organizations sort their patch queue by CVSS. That’s like sorting your grocery list by price. The 9.8 DNS RCE on your only DC is more urgent than a 9.1 Office flaw on a workstation sitting behind a corporate firewall. Here’s the reachability priority for September:

  1. Internet-facing servers. SSTP, DNS, DHCP, Exchange, SharePoint — patch first, because the exploit doesn’t require domain credentials.
  2. Domain controllers. Netlogon, DNS, Kerberos — patch next, because the exploitation gives you the DC.
  3. Infrastructure services. DHCP (internal), MSMQ, NFS, RRAS — patch based on which roles still exist in your environment.
  4. Workstations. Office Preview Pane flaws, Update Stack, ALPC — patch last among the RCEs, because they require local access or user interaction.

The two KEV-zero-days (Update Stack and ALPC) are in tier 4 but carry “exploitation detected” flags and BOD 26-04 forensic-triage requirements, so they deserve at least a week’s attention.

What most orgs get wrong

“We don’t run DNS, DHCP, or MSMQ.” You almost certainly run at least one. Windows Server defaults include DNS and DHCP roles. MSMQ ships with Windows and is often left running even when nothing uses it. Disable what you don’t need. That’s a cheaper mitigation than patching.

“We patched last Tuesday.” September’s patches are cumulative. But many orgs apply the cumulative update and don’t verify which roles are actually patched. A DC with patched DNS but unpatched Netlogon is still wormable. Check the build number on every role, not just the OS.

“ShieldBreak is patched, so we’re good.” ShieldCrash proved Microsoft’s patch incomplete. Check your Malware Protection Engine version — the fix landed in 1.1.26080.3. If you’re still on an earlier build and ShieldCrash’s attack path is active, you’re exposed even after Patch Tuesday.

The takeaway

974 CVEs is a press release number. The 20 wormable RCEs are the operational reality. Patch in reachability order — internet-facing first, domain controllers second, infrastructure third, workstations last — and verify every role on every machine, not just the OS build. Then watch the Malware Protection Engine version for the second patch after the patch.

And if you want a single metric to drive your patch queue next month: count the unauthenticated, network-reachable RCEs per asset, not the sum of all CVSS scores in the bulletin.

References